HomeSecurityPhishing campaign targets banking app users

Phishing campaign targets banking app users

Phishing

Nowadays, many people use banking apps on their mobile phones to carry out various transactions. The increased use of these apps has not gone unnoticed by cybercriminals , who send phishing messages to users with the aim of deceiving them and getting them to give up credentials .

According to Lookout, approximately 4,000 smartphone have fallen victim to this phishing campaign and opened the malicious links included in these phishing emails. Most of the users were located in the US and Canada.

The phishing campaign is carried out via an SMS, which encourages the banking app user to visit fake sites that closely resemble the official sites of major American and Canadian banks.

The hacking group left part of its infrastructure exposed, and Lookout was able to track down nearly 4,000 IP addresses that visited the phishing sites. Researchers don't know if any financial losses were incurred.

How is fraud committed?

Phishing SMS messages claim that the bank's security system has detected unusual activity on the user's account. For this reason, the user must follow a URL to check what is happening. In reality, it is a trick to get users to give up their credentials.

According to researchers, the criminals do not know which bank their potential victim works with. But they send a lot of spam messages with the names of different banks. So some of the attacks are successful, because the bank matches the customer. Many of these users, who fall victim to the attack, open the malicious link.

As we said above, these sites look very similar to the official ones. They include elements and links that lead to pages that one would expect to see in banking applications and sites. There are also warnings about security and privacy.

Phishing campaign targets banking app users

Phishing sites ask users to provide usernames and passwords as well as other information, such as card expiration date , to confirm the user's identity.

All of this information can help hackers steal the victim's account information, make transactions with their money, and even sell the information to other users on hacking forums.

We don't yet know who is behind the phishing campaign, but researchers say the attacks aren't particularly sophisticated. However, they are successful.

“This particular campaign shows us how easy it is for an inexperienced hacker to carry out phishing attacks by purchasing an off-the-shelf phishing kit. The attacker can then target multiple victims via SMS messages,” said Apurva Kumar, security engineer at Lookout.

Lookout has notified all banks involved in the phishing campaign. All malicious sites are now down.

Many other hackers may try to carry out a similar attack. For this reason, users should be very careful and not open links found in emails and messages, but search for the address on the Internet.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS